Tools & Products

Claude Code 2.1.288 Ships --max-findings Flag for /code-review: Reducing Noise in Automated PR Audits

Anthropic published Claude Code CLI version 2.1.288, introducing the --max-findings configuration to the /code-review command to suppress alert fatigue and prioritize actionable high-severity defects in continuous integration pipelines.

By FreakVinci · 2026-10-03 · 11 min read

Anthropic released Claude Code version 2.1.288, bringing a targeted configuration flag to its automated review command: --max-findings (or -n).

The addition addresses a widespread operational complaint among development teams adopting AI code reviewers: alert fatigue. When an automated agent reviews an extensive pull request, unconstrained output often generates 30 to 50 nitpicks regarding variable names, import order, and whitespace. This wall of text frequently buries genuine security flaws, SQL injection risks, and asynchronous race conditions.


Command Syntax and Flags in Version 2.1.288

The updated command allows engineers and CI runners to cap the total volume of reported findings while ensuring only the most critical defects appear:

# Limit review output to the top 5 most critical findings
claude code /code-review --max-findings 5

# Shorthand notation restricted to high and critical severity items
claude code /code-review -n 3 --severity high

# Generate machine-readable JSON output for GitHub Actions annotations
claude code /code-review -n 5 --format json > review-results.json

Finding Triage and Severity Ranking Heuristics

When a git changeset contains more potential issues than the specified --max-findings ceiling, Claude Code 2.1.288 evaluates each finding through an internal four-tier priority hierarchy:

┌────────────────────────────────────────────────────────┐
│               Claude Code Finding Hierarchy            │
├───────────┬────────────────────────────────────────────┤
│ Priority 1│ Critical Vulnerabilities                   │
│ (Score 10)│ (SQLi, SSRF, Hardcoded Secrets, Auth Bypass)│
├───────────┼────────────────────────────────────────────┤
│ Priority 2│ Concurrency & Memory Bugs                  │
│ (Score 8) │ (Data races, Deadlocks, Unhandled Promises)│
├───────────┼────────────────────────────────────────────┤
│ Priority 3│ Logic Invariants & Edge Cases              │
│ (Score 5) │ (Off-by-one errors, Null pointer traps)    │
├───────────┼────────────────────────────────────────────┤
│ Priority 4│ Code Style & Conventions                   │
│ (Score 2) │ (Variable naming, JSDoc omissions, imports)│
└───────────┴────────────────────────────────────────────┘

If a pull request introduces one SQL injection risk, two unhandled promise rejections, and twenty stylistic inconsistencies, running claude code /code-review -n 3 guarantees the security vulnerability and the two promise defects are reported, while the minor stylistic notes are suppressed.


Integrating --max-findings into GitHub Actions CI

Here is a production-ready workflow configuration demonstrating how to use the new flag in an automated pull request pipeline:

name: Automated AI Code Review

on:
  pull_request:
    types: [opened, synchronize]

jobs:
  review:
    runs-on: ubuntu-latest
    steps:
      - name: Checkout Repository
        uses: actions/checkout@v4
        with:
          fetch-depth: 0

      - name: Setup Node.js
        uses: actions/setup-node@v4
        with:
          node-version: '20'

      - name: Install Claude Code CLI
        run: npm install -g @anthropic-ai/claude-code@2.1.288

      - name: Execute Curated Code Review
        env:
          ANTHROPIC_API_KEY: ${{ secrets.ANTHROPIC_API_KEY }}
        run: |
          claude code /code-review \
            --max-findings 5 \
            --severity medium \
            --format github \
            --base origin/${{ github.base_ref }}

Performance Improvements in 2.1.288

In addition to the flag, version 2.1.288 refactors the underlying git diff parser:

  • Incremental Index Caching: Rather than feeding raw unparsed unified diff text to the LLM, Claude Code generates an abstract syntax tree (AST) delta, reducing prompt token counts by 35%.
  • Review Latency: Diffs containing 1,200 lines across 14 files now complete analysis in 4.8 seconds, down from 7.9 seconds in version 2.1.280.